Mew: Enabling Large-Scale and Dynamic Link-Flooding Defenses on Programmable Switches

被引:6
|
作者
Zhou, Huancheng [1 ]
Hong, Sungmin [1 ]
Liu, Yangyang [2 ]
Luo, Xiapu [2 ]
Li, Weichao [3 ]
Gu, Guofei [1 ]
机构
[1] Texas A&M Univ, SUCCESS Lab, College Stn, TX 77843 USA
[2] Hong Kong Polytech Univ, Hong Kong, Peoples R China
[3] Peng Cheng Lab, Shenzhen, Peoples R China
基金
美国国家科学基金会;
关键词
D O I
10.1109/SP46215.2023.10179404
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Link-flooding attacks (LFAs) can cut off the Internet connection to selected server targets and are hard to mitigate because adversaries use normal-looking and low-rate flows and can dynamically adjust the attack strategy. Traditional centralized defense systems cannot locally and efficiently suppress malicious traffic. Though emerging programmable switches offer an opportunity to bring defense systems closer to targeted links, their limited resource and lack of support for runtime reconfiguration limit their usage for link-flooding defenses. We present Mew1, a resource-efficient and runtime adaptable link-flooding defense system. Mew can counter various LFAs even when a massive number of flows are concentrated on a link, or when the attack strategy changes quickly. We design a distributed storage mechanism and a lossless state migration mechanism to reduce the storage bottleneck of programmable networks. We develop cooperative defense APIs to support multi-grained codetection and co-mitigation without excessive overhead. Mew's dynamic defense mechanism can constantly analyze network conditions and activate corresponding defenses without rebooting devices or interrupting other running functions. We develop a prototype of Mew by using real-world programmable switches, which are located in five cities. Our experiments show that the real-world prototype can defend against large-scale and dynamic LFAs effectively.
引用
收藏
页码:3178 / 3192
页数:15
相关论文
共 50 条
  • [21] Large-Scale Programmable Synthesis of PbS Quantum Dots
    Preske, Amanda
    Liu, Jin
    Prezhdo, Oleg V.
    Krauss, Todd D.
    CHEMPHYSCHEM, 2016, 17 (05) : 681 - 686
  • [22] Enabling Serverless Deployment of Large-Scale AI Workloads
    Christidis, Angelos
    Moschoyiannis, Sotiris
    Hsu, Ching-Hsien
    Davies, Roy
    IEEE ACCESS, 2020, 8 : 70150 - 70161
  • [23] ImageProof: Enabling Authentication for Large-Scale Image Retrieval
    Guo, Shangwei
    Xu, Jianliang
    Zhang, Ce
    Xu, Cheng
    Xiang, Tao
    2019 IEEE 35TH INTERNATIONAL CONFERENCE ON DATA ENGINEERING (ICDE 2019), 2019, : 1070 - 1081
  • [24] Affinity Chromatography: An Enabling Technology for Large-Scale Bioprocessing
    Lacki, Karol M.
    Riske, Frank J.
    BIOTECHNOLOGY JOURNAL, 2020, 15 (01)
  • [25] Enabling large-scale wireless broadband: The case for TAPs
    Karrer, R
    Sabharwal, A
    Knightly, E
    ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2004, 34 (01) : 27 - 32
  • [26] Enabling Large-Scale Simulations With the GENESIS Neuronal Simulator
    Crone, Joshua C.
    Vindiola, Manuel M.
    Yu, Alfred B.
    Boothe, David L.
    Beeman, David
    Oie, Kelvin S.
    Franaszczuk, Piotr J.
    FRONTIERS IN NEUROINFORMATICS, 2019, 13
  • [27] Hermes: Enabling efficient large-scale simulation in MATSim
    Graur, Dan
    Bruno, Rodrigo
    Bischoff, Joschka
    Rieser, Marcel
    Scherr, Wolfgang
    Hoefler, Torsten
    Alonso, Gustavo
    12TH INTERNATIONAL CONFERENCE ON AMBIENT SYSTEMS, NETWORKS AND TECHNOLOGIES (ANT) / THE 4TH INTERNATIONAL CONFERENCE ON EMERGING DATA AND INDUSTRY 4.0 (EDI40) / AFFILIATED WORKSHOPS, 2021, 184 : 635 - 641
  • [28] Enabling Large-scale Heterogeneous Collaboration with Opportunistic Communications
    Cladera, Fernando
    Ravichandran, Zachary
    Miller, Ian D.
    Hsieh, M. An
    Taylor, C. J.
    Kumar, Vijay
    2024 IEEE INTERNATIONAL CONFERENCE ON ROBOTICS AND AUTOMATION, ICRA 2024, 2024, : 2610 - 2616
  • [29] APPLICATIONS ENABLING THE LARGE-SCALE DEPLOYMENT OF GIGABIT NETWORKS
    LYLES, JB
    RICHER, I
    STERBENZ, JPG
    CHEUNG, NK
    IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 1995, 13 (05) : 765 - 767
  • [30] A CLASS OF ADAPTIVE ROUTING AND LINK ASSIGNMENT ALGORITHMS FOR LARGE-SCALE NETWORKS WITH DYNAMIC TOPOLOGY
    CAIN, JB
    NIETO, JW
    NOAKES, MD
    ALTHOUSE, EL
    1989 IEEE MILITARY COMMUNICATIONS CONFERENCE, VOLS 1-3: BRIDGING THE GAP : INTEROPERABILITY, SURVIVABILITY, SECURITY, 1989, : 671 - 676